PT-2023-5338 · Apache · Apache Airflow Sqoop Provider

·

CVE-2023-27604

·

Published

2023-08-25

·

Updated

2026-07-07

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Airflow Sqoop Provider versions prior to 4.0.0
Description The issue is related to insufficient input validation, which can be exploited by a remote attacker to execute arbitrary code. This can be achieved by passing parameters with connections, making it possible to implement RCE attacks via sqoop import --connect, and obtain Airflow server permissions. The attacker needs to be logged in and have authorization to create or edit connections.
Recommendations To resolve the issue, upgrade to a version that is not affected, specifically version 4.0.0 or later. As a temporary workaround, consider restricting access to the sqoop import --connect command to minimize the risk of exploitation. Additionally, limit the ability to create or edit connections to authorized personnel only.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05966
CVE-2023-27604
GHSA-G3M9-PR5M-4CVP
PYSEC-2026-1142

Affected Products

Apache Airflow Sqoop Provider